Tech News
← Back to articles

Malicious GhostPoster browser extensions found with 840,000 installs

read original related products more articles

Another set of 17 malicious extensions linked to the GhostPoster campaign has been discovered in Chrome, Firefox, and Edge stores, where they accumulated a total of 840,000 installations.

The GhostPoster campaign was first reported by Koi Security researchers in December. They found 17 extensions that were hiding malicious JavaScript code in their logo images, which monitored browser activity and planted a backdoor.

The code fetches a heavily obfuscated payload from an external resource, which tracks the victim’s browsing activity, hijacks affiliate links on major e-commerce platforms, and injects invisible iframes for ad fraud and click fraud.

A new report from browser security platform LayerX indicates that the campaign is still ongoing despite being exposed, and the following 17 extensions are part of it:

Google Translate in Right Click – 522,398 installs

– 522,398 installs Translate Selected Text with Google - 159,645 installs

- 159,645 installs Ads Block Ultimate – 48,078 installs

– 48,078 installs Floating Player – PiP Mode – 40,824 installs

– 40,824 installs Convert Everything – 17,171 installs

– 17,171 installs Youtube Download – 11,458 installs

... continue reading